Executive brief
A vulnerability in the Linux kernel's namespace file system could allow privileged services to improperly access information from other services. This flaw breaks the isolation between different parts of the operating system, potentially leading to unauthorized data access or a full system compromise. Organizations should apply the latest kernel security patches to ensure proper service isolation.
Technical details
A vulnerability exists in the Linux kernel's namespace filesystem (nsfs) due to insufficient permission checks in the nsfs_fh_to_dentry function. The root cause is that the kernel previously relied on a simple CAP_SYS_ADMIN check which allowed privileged services to view namespaces belonging to other privileged services. An attacker with local access could exploit this to bypass namespace isolation and leak sensitive information. The fix replaces the existing check with the may_see_all_namespaces() helper to enforce stricter centralized policy. Patches have been released for affected stable branches including 6.19.9 and later.
Affected products
- Linux Linux Kernel 6.18 to 6.19.9
Timeline
- 2026-02-26: other: Vulnerability fixed in upstream source code
- 2026-05-08: disclosed: CVE published
- 2026-05-26: advisory: NVD analysis updated